Daily Security Intel

Archives
Log in
Subscribe
July 5, 2026

[SecurityIntel] 05 Jul | AI-Driven JadePuffer Ransomware Automates Entire Attack Lifecycle

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Sunday, July 05, 2026

INTEL CONFIDENCE  88%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

AI-Driven JadePuffer Ransomware Automates Entire Attack Lifecycle

CRITICAL

5

C2 IPs

42

OTX IOCs

3

ARTICLES

■ ANALYST TLDR

Today's threat landscape marks a significant evolution with the discovery of JadePuffer ransomware, which utilized an automated AI LLM agent to execute an entire attack lifecycle. Meanwhile, North Korean state-sponsored actors are targeting software developers via the PolinRider campaign, publishing 108 malicious packages and extensions across npm, Packagist, Go, and Google Chrome. Additionally, a U.S. government entity paid a $1 million ransom to the Kairos group, highlighting the ongoing severity of data-theft extortion campaigns.

■ CRITICAL STORIES

CRITICAL#1

JadePuffer ransomware used AI agent to automate entire attack

This represents the first documented case of an LLM agent automating a ransomware attack from end to end, signaling a dangerous shift toward highly scalable, machine-speed cyber threats.

HIGH#2

North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign

North Korean actors are actively poisoning open-source package repositories and browser extension stores, directly targeting developer environments to gain initial access.

HIGH#3

U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case

A leaked negotiation and blockchain analysis reveal a federal entity paid a massive ransom to prevent data exposure, demonstrating the high-stakes impact of Kairos extortion operations.

■ CVEs IDENTIFIED

[CVE-TBD]

JadePuffer Ransomware — Automated execution and file encryption via AI agent

Critical

[CVE-TBD]

Google Chrome (Extensions) — Malicious browser extension execution leading to credential and data theft

High

[CVE-TBD]

npm / Packagist / Go Packages — Supply chain compromise via malicious package dependency resolution

High

[CVE-TBD]

Kairos Extortion Target — Unauthorized access and data exfiltration leading to extortion

High

■ THREAT ACTORS

JadePuffer

Ransomware Group

Utilizing automated LLM AI agents to conduct end-to-end ransomware attacks

Kairos

Extortion Group

Conducting data-theft extortion campaigns targeting U.S. government entities

North Korean Hackers (Contagious Interview / PolinRider)

State-Sponsored

Publishing malicious packages and browser extensions to compromise developer environments

■ ATT&CK TTPs

T1486
Data Encrypted for Impact | JadePuffer ransomware encrypting victim systems
T1195.001
Supply Chain Compromise: Compromise Software Dependencies and Development Tools | North Korean actors publishing malicious npm, Packagist, and Go packages
T1176
Browser Extensions | Malicious Google Chrome extensions deployed in PolinRider campaign
T1048
Exfiltration Over Alternative Protocol | Kairos group stealing and exfiltrating data for extortion
T1059
Command and Scripting Interpreter | AI agent executing automated scripts and commands

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

npm / Packagist / Go — Malicious package execution (PolinRider) — THN

[P1 PATCH NOW]≤24h

Google Chrome — Malicious extensions (PolinRider) — THN

[P2 PATCH NOW]≤72h

Enterprise Endpoints — AI-driven automated ransomware (JadePuffer) — BC

■ RECOMMENDED ACTIONS TODAY

1[P1] Audit all developer environments for the 108 malicious PolinRider packages across npm, Packagist, and Go registries, and immediately block/remove them.
2[P1] Implement strict application control policies on Google Chrome to prevent the installation of unapproved or newly published third-party extensions.
3[P2] Deploy advanced behavioral monitoring and endpoint detection and response (EDR) tools to identify anomalous automated command execution associated with AI-driven JadePuffer ransomware.
4[P2] Restrict outbound data transfers and enforce strict data loss prevention (DLP) controls to mitigate the risk of data-theft extortion campaigns like Kairos.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 06 Jul | Flipper Zero Shifts to Community-Led Firmware Development Older → [SecurityIntel] 04 Jul | Critical Bad Epoll Linux Kernel Vulnerability Patched
Powered by Buttondown, the easiest way to start and grow your newsletter.